CVE-2024-29868: Apache StreamPipes – Use of Cryptographically Weak PRNG in Recovery Token Generation
Alessandro Albani2024-06-25T12:20:11+02:00Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism.
This issue affects Apache StreamPipes from version 0.69.0 through 0.93.0.
Users are recommended to upgrade to version 0.95.0, which fixes the issue.